Cross-Product Tag Behavior
Tags created in one Tenable product can influence how assets appear, are scored, and are governed in other Tenable products, but the direction of flow matters. This topic explains how tags move across the Tenable platform, what capabilities they carry at each layer, and where the boundaries are.
How Tenable One Vulnerability Management Tags Flow into Tenable One
Tags created in Tenable One Vulnerability Management (cloud) automatically synchronize into Tenable One and appear as Business Context segments in Tenable One dashboards and Tenable Exposure Management.
- A tag value is created in Tenable One Vulnerability Management (manually or via a dynamic rule).
- Assets that match the tag are grouped under that Category:Value pair.
- On the next sync cycle, the tag and its asset membership propagate to Tenable One.
- In Tenable One, each tag value becomes a Business Context segment with its own Cyber Exposure Score, Asset Exposure Score, Asset Criticality Rating distribution, and remediation maturity score.
Business Context in Tenable One
Within Tenable One, each tag value from Tenable One Vulnerability Management becomes a scoped view of your risk posture. For each tag, Tenable One calculates:
- Cyber Exposure Score (0–1000) — overall exposure score for assets with that tag
- Asset Exposure Score (0–1000) — asset-level risk weighting
- Asset Criticality Rating (1–10) — asset criticality within the tag segment
- Vulnerability Priority Rating (0.1–10.0) — vulnerability exploitability weighting
- Assessment Maturity (grades A–F) — how thoroughly assets in the segment are being scanned
- Remediation Maturity (grades A–F) — how effectively vulnerabilities in the segment are being closed
These per-tag scores let security leaders benchmark different business units, environments, or compliance scopes against each other — for example, comparing the Cyber Exposure Score of your production environment tag against your development environment tag.
Tag-Scoped Risk Metrics
| Metric | Range | Meaning |
|---|---|---|
| Cyber Exposure Score | 0–1000 | Overall cyber exposure for the tag segment (lower is better; 0 = no exposure) |
| Asset Exposure Score | 0–1000 | Asset exposure weighting — combines Asset Criticality Rating and Vulnerability Priority Rating |
| Asset Criticality Rating | 1–10 | Asset criticality based on device type, internet exposure, and other signals (higher = more critical) |
| Vulnerability Priority Rating | 0.1–10.0 | Vulnerability exploitability and threat context (higher = more urgent to remediate) |
| Assessment Maturity | A–F | Scan coverage and frequency for assets in the segment (A = best coverage) |
| Remediation Maturity | A–F | Speed and thoroughness of remediation activity in the segment (A = fastest remediation) |
Tags in Tenable Exposure Management
Tenable Exposure Management presents three tag types: Tenable One Tags (native, fully editable), Tenable One Vulnerability Management Tags (read-only), and External Tags (from Cloud Security, Identity Exposure, or third parties — asset-level only). See Tags in Tenable Exposure Management for the full capability comparison.
The data flow from Tenable One Vulnerability Management into Tenable Exposure Management follows five steps.
- Tags and asset data are ingested from Tenable One Vulnerability Management into Tenable One.
- Tag membership is applied to assets in the Tenable One inventory.
- Risk scores (Cyber Exposure Score, Asset Exposure Score, Asset Criticality Rating) are calculated per tag segment.
- Tags appear in Tenable Exposure Management Inventory, where they can filter assets and scope Exposure View Cards.
- Dashboard widgets reflect tag-scoped data within up to 24 hours of membership changes.
Only Tenable One Tags support Dashboard filtering in Tenable Exposure Management. Tenable One Vulnerability Management Tags and External Tags cannot be used as Dashboard-level filters.
Using Risk Scores as Tag Rule Filters
When your Tenable One Vulnerability Management instance has an active Tenable One license, Asset Criticality Rating and Asset Exposure Score become available as tag rule filter inputs. This creates a feedback loop: risk scores drive tag membership, and tags drive access control and reporting.
For example, a tag rule built on the Asset Criticality Rating and Asset Exposure Score filters — expressed in the rule builder as ACR ≥ 8 AND AES ≥ 650 — automatically tags the highest-risk, highest-exposure assets in your environment. As scores change over time — assets become more critical, new vulnerabilities are discovered, patches are applied — tag membership updates automatically on the next rule evaluation cycle.
Cross-Product Behavior Summary
The following table summarizes tag capabilities across products. Tenable One Tags refers to tags created natively in Tenable Exposure Management; Tenable One Vulnerability Management Tags refers to tags created in Tenable One Vulnerability Management that sync to Tenable One; Tenable Security Center Asset Tags refers to on-premises Tenable Security Center's typed asset-grouping Asset Tags; External Tags refers to third-party tags surfaced in Tenable Exposure Management; Tenable One Attack Surface Management Tags refers to tags within Tenable One Attack Surface Management.
| Capability | Tenable One Vulnerability Management Tags | Tenable One Tags | External Tags (Tenable Exposure Management) | Tenable Security Center Asset Tags | Tenable One Attack Surface Management Tags |
|---|---|---|---|---|---|
| Structured Category:Value | Yes | Yes | Varies by source | No (typed asset list) | No (name + value type) |
| Dynamic rules engine | Yes | Yes | No | Yes — Dynamic and Combination Asset Tags | No |
| Flows to Tenable One | Yes | Native | Not applicable (already in Tenable Exposure Management) | Partially — via optional Tenable One Synchronization (IPv4 Static/Dynamic Asset Tags only, requires a Tenable Lumin or Tenable One license) | No |
| Business Context / Cyber Exposure Score per tag | Yes | Yes | No | No | No |
| Exposure View Card scoping | Yes | Yes | No | No | No |
| Dashboard filtering (Tenable Exposure Management) | No | Yes | No | No | No |
| Inventory search / filter | Yes (Tenable Exposure Management, Tenable One Vulnerability Management) | Yes | Yes (Tenable Exposure Management inventory) | Yes (Tenable Security Center only) | Yes (Tenable One Attack Surface Management only) |
| Role-based access control / access group scoping | Yes (Tenable One Vulnerability Management + Tenable Exposure Management) | Yes | No | Shared with specific users per local security policy | No |
| API management | Yes (REST API) | Yes (via Tenable One Vulnerability Management API) | No (source system) | Yes (Tenable Security Center REST API — asset resource) |
Yes (Tenable One Attack Surface Management REST API) |